Privacy & Cookie Policy

This is the English version of our privacy policy. Dansk version her.

Data controllerMit Beredskab ApS, CVR 42299529
Contactkontakt@mitberedskab.dk
Websitehttps://mitberedskab.dk [Bekræftet 29. mar. 2026]
Version1.4
Created2026-02-11
Last updated2026-08-21

Section 1. Introduction and scope

This privacy and cookie policy describes how Mit Beredskab ApS (hereinafter “MitBeredskab”, “we”, “us” or “our”) collects, processes and protects personal data when you visit our website mitberedskab.dk, contact us, or otherwise interact with us as a potential or existing customer.

This policy covers: The website mitberedskab.dk, including contact forms, web analytics, cookies, sales, marketing, customer administration and contract conclusion. In these contexts, MitBeredskab is the data controller.

This policy does not cover: The web application app.mitberedskab.dk and the associated mobile app. Use of the alerting app is subject to a separate and enhanced data processing agreement entered into directly between MitBeredskab and the individual organisational customer (school, municipality or company) pursuant to GDPR Article 28. In this context, MitBeredskab acts as a data processor, and the organisation is the data controller for the personal data processed in the app. If you have questions about how your data is processed in the app, please contact your workplace or school.


Section 2. Data controller and contact information

The data controller for the processing of personal data described in this policy is:

Mit Beredskab ApS CVR: 42299529 Niels Jernes Vej 10, 9220 Aalborg Øst, Denmark Email: kontakt@mitberedskab.dk Website: https://mitberedskab.dk [Bekræftet 29. mar. 2026]

We have not currently appointed a Data Protection Officer (DPO), but enquiries about personal data are handled with the highest priority.


Section 3. What personal data do we process?

SituationDataPurpose
You visit the websiteIP address (anonymised), page views, device typeWeb analytics and website improvement (only with consent)
You fill in the contact formName, email, company, messageResponding to your enquiry
You become a customer (CRM)Name, email, phone, company, company address, correspondenceSales, invoicing and customer administration
You sign an agreementName, email, IP address, signatureDigital signing of contracts via BoldSign

3.1 What we do not collect

We do not collect location data, health information, national identification numbers (CPR) or other special categories of personal data via the website.


PurposeLegal basisLegitimate interest (if applicable)
Responding to enquiriesArt. 6(1)(b): pre-contractual measures
Sales, invoicing and CRMArt. 6(1)(b): performance of contract
Digital signing of agreementsArt. 6(1)(b): performance of contract
Web analytics (Google Analytics)Art. 6(1)(a): consent
Remarketing and advertising (Facebook, LinkedIn, Google Ads)Art. 6(1)(a): consent
Technical operation and debuggingArt. 6(1)(f): legitimate interestEnsuring system stability and availability, which is critical for an alerting service
Direct marketing to existing customersArt. 6(1)(f): legitimate interestInformation about relevant product updates and security improvements. You can always unsubscribe.
Automation of internal workflowsArt. 6(1)(f): legitimate interestEfficient and secure handling of customer data between our systems

Section 5. Recipients and sub-processors

We do not disclose personal data to third parties for their own purposes. We use the following sub-processors as part of our operations:

ServiceProviderPurposeLocation
HostingScaleway (SCW)Server infrastructure and emailEU (France)
Web analyticsGoogle AnalyticsTraffic analysis on mitberedskab.dkEU/USA*
CRMPipedriveSales and customer administrationEU (Estonia/Ireland)
Contact formFillout.com (Restly, Inc.)Receiving enquiries via the websiteUSA*
Digital signingBoldSign (Syncfusion, Inc.)Signing contracts and agreementsEU (Netherlands)**
AutomationMake.com (Celonis SE)Automation of workflows between systemsEU***
Internal communicationGoogle WorkspaceEmail and document sharing (internal)EU/USA*
AI toolsAmazon Web Services (Bedrock)AI-assisted preparation of documents and communicationsEU (Frankfurt)****
Live chatCrisp IM SARLCustomer support via the website chat window (loads only on click)EU (France)
RemarketingMeta Platforms (Facebook Pixel)Advertising and remarketing on Facebook/InstagramEU/USA*****
RemarketingLinkedIn (Insight Tag)Advertising and remarketing on LinkedInEU/USA*****
RemarketingGoogle Ads (Conversion Tracking)Advertising and remarketing on GoogleEU/USA*****

* Third-country transfers (Google and Fillout): Google LLC and Fillout.com (Restly, Inc.) are certified under the EU-U.S. Data Privacy Framework (DPF), which the European Commission has approved as providing an adequate level of protection (adequacy decision of 10 July 2023). Fillout.com also uses the European Commission’s Standard Contractual Clauses (SCC) as a supplementary transfer mechanism.

** BoldSign: BoldSign offers EU data residency with a data centre in the Netherlands. Our account is configured with the EU as data location, so documents and personal data are stored and processed within the EU.

*** Make.com: Make.com (owned by Celonis SE, Germany) is ISO 27001-certified and DPF-certified. Our account uses an EU data centre. Celonis SE uses Standard Contractual Clauses (SCC) for any transfers to sub-processors outside the EU.

**** Amazon Web Services (Bedrock): We use AI tools via Amazon Web Services (AWS) with a data centre in the EU (Frankfurt). Personal data is processed exclusively on European servers. Data is not retained by the AI provider after processing (zero data retention) and is not used for training AI models.

***** Meta, LinkedIn and Google Ads: Meta Platforms Ireland Ltd., LinkedIn Ireland Unlimited Company and Google LLC are all certified under the EU-U.S. Data Privacy Framework (DPF). Remarketing cookies and pixels are activated only after your active consent via our cookie banner.


Section 6. Transfers to third countries

Our primary infrastructure is located in the EU (Scaleway in France, BoldSign in the Netherlands, Make.com in the EU, Pipedrive in Estonia/Ireland). No transfer of this data to countries outside the EU/EEA takes place.

For services provided by Google (Analytics, Ads, Workspace), Meta (Facebook), LinkedIn and Fillout.com, transfers to the USA may occur. These transfers are protected by the EU-U.S. Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses, cf. Section 5 above. Should the DPF framework be invalidated, we will immediately implement alternative transfer mechanisms or switch to EU-based alternatives.


Section 7. Retention period

  • Contact form enquiries: Deleted no later than 12 months after the conclusion of the enquiry, unless a customer relationship has been established.
  • CRM data (Pipedrive): Retained for as long as the customer relationship is active. Upon termination, data is deleted no later than 12 months afterwards, unless legislation requires longer retention (e.g. the Danish Bookkeeping Act: 5 years).
  • Signed documents (BoldSign): Retained for as long as necessary for the contractual relationship and any legal requirements.
  • Web analytics data (Google Analytics): Retained for up to 14 months, after which data is automatically anonymised.
  • Marketing cookies (Facebook, LinkedIn, Google Ads): Cookies expire automatically after up to 2 years depending on the provider. Data is deleted by the provider in accordance with their respective data processing policies. Cookies are only activated with your consent.

Section 8. Your rights

As a data subject, you have the following rights under the GDPR:

RightDescription
Access (Art. 15)You have the right to obtain confirmation as to whether we process personal data about you and, if so, access to the data.
Rectification (Art. 16)You have the right to have inaccurate data about you corrected.
Erasure (Art. 17)In certain cases, you have the right to have data about you deleted.
Restriction (Art. 18)In certain cases, you have the right to have the processing of your data restricted.
Data portability (Art. 20)You have the right to receive your data in a structured, commonly used and machine-readable format.
Objection (Art. 21)You have the right to object to processing based on legitimate interest, including direct marketing.
Withdrawal of consentWhere processing is based on consent (e.g. cookies), you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

You can exercise your rights by contacting us at kontakt@mitberedskab.dk. We will respond to enquiries within 30 days.


Section 9. Complaint to the Danish Data Protection Agency

If you are dissatisfied with our processing of your personal data, you have the right to lodge a complaint with:

Datatilsynet (Danish Data Protection Agency) Carl Jacobsens Vej 35 2500 Valby, Denmark Phone: +45 33 19 32 00 Email: dt@datatilsynet.dk Website: https://www.datatilsynet.dk [Bekræftet 29. mar. 2026]

We encourage you to contact us first so that we can attempt to resolve any disagreements directly.


Section 10. Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration or disclosure, cf. GDPR Article 32. Our measures include:

  • Encryption in transit: All communication between users and our systems is encrypted with TLS/SSL.
  • Encryption at rest: Data is encrypted at server level by our hosting providers.
  • Access control: Access to personal data is restricted to authorised employees following the principle of least privilege.
  • Confidentiality: All employees with access to personal data are subject to confidentiality obligations.
  • Ongoing evaluation: We regularly assess and update our security measures.

In the event of a personal data breach, we will notify the Danish Data Protection Agency within 72 hours in accordance with GDPR Article 33. If the breach poses a high risk to those affected, they will also be notified directly, cf. Article 34.


Section 11. Automated decision-making

We do not carry out automated decision-making, including profiling, which has legal effects or similarly significantly affects data subjects, cf. GDPR Article 22.


Section 12. Is it mandatory or voluntary to provide personal data?

Providing information via the contact form is voluntary but necessary for us to respond to your enquiry. Providing information in connection with contract conclusion (including digital signing) is a contractual prerequisite for the delivery of our services.


13.1 What are cookies?

Cookies are small text files stored on your device when you visit a website. They are used to make the website function correctly and to collect statistics about the use of the website.

13.2 Cookies on mitberedskab.dk

Cookie nameProviderTypeLifetimePurpose
cookie-consentMit BeredskabNecessary12 monthsRemembers your cookie choice (stored in browser localStorage)
cookie-consent-metaMit BeredskabNecessary12 monthsTimestamp and version of your cookie choice
_gaGoogle AnalyticsStatistics2 yearsDistinguishes between unique visitors
_ga_*Google AnalyticsStatistics2 yearsPersists session state (GA4)
_gidGoogle AnalyticsStatistics24 hoursDistinguishes between users and records page views
crisp-client*Crisp IM SARLNecessaryUp to 6 monthsKeeps your support conversation alive between page views
_fbpMeta Platforms (Facebook Pixel)Marketing3 monthsIdentifies browsers for Facebook advertising
_fbcMeta Platforms (Facebook Pixel)Marketing2 yearsStores click ID from Facebook ads
lastExternalReferrerMeta Platforms (Facebook Pixel)MarketingUntil deletedMost recent external referrer for Facebook advertising
lastExternalReferrerTimeMeta Platforms (Facebook Pixel)MarketingUntil deletedTimestamp of the most recent external referral (Facebook advertising)
li_sugrLinkedIn (Insight Tag)Marketing3 monthsIdentifies browsers for LinkedIn advertising
UserMatchHistoryLinkedIn (Insight Tag)Marketing30 daysLinkedIn Ads optimisation
bcookieLinkedIn (Insight Tag)Marketing1 yearBrowser ID for the LinkedIn Insight Tag
lidcLinkedIn (Insight Tag)Marketing24 hoursRouting for the LinkedIn Insight Tag
_gcl_auGoogle Ads (Conversion Tracking)Marketing3 monthsStores conversion data from Google Ads

The table covers both cookies proper and equivalent storage technologies (e.g. browser localStorage), which the Danish Cookie Executive Order treats alike. Names marked with \* cover a family of keys whose suffix varies.

Statistics and marketing cookies are only activated after your active consent via our cookie banner. You can change or withdraw your consent at any time via the cookie banner.

  • Necessary cookies: Section 3(2) of the Danish Cookie Executive Order (exempt from consent requirement).
  • Statistics cookies: GDPR Article 6(1)(a) (consent), cf. Section 3(1) of the Danish Cookie Executive Order.
  • Marketing cookies: GDPR Article 6(1)(a) (consent), cf. Section 3(1) of the Danish Cookie Executive Order. Used for remarketing and advertising on Facebook, LinkedIn and Google.

13.4 How to delete cookies that have already been set

Withdrawing your consent via the cookie banner stops us from setting new cookies, but it does not automatically remove those already stored in your browser. You delete those yourself:

  • Open your browser’s settings and find the privacy section (typically “Privacy and security” or “Clear browsing data”).
  • Choose to delete cookies and site data for mitberedskab.dk, or for all websites. “Site data” also covers localStorage, which this policy treats on equal footing with cookies.
  • The exact steps vary between browsers (Chrome, Safari, Firefox, Edge); search for “delete cookies” in your browser’s own help function for step-by-step instructions.

Note: deleting cookies also deletes your saved cookie choice, and the banner will appear again on your next visit.


Section 14. Changes to this policy

We may update this privacy and cookie policy from time to time. In the event of significant changes, we will inform you via a prominent notice on our website before the changes take effect. The date of the most recent update appears at the top of this document.


Section 15. Contact

If you have questions about this policy or our processing of personal data, please contact us:

Mit Beredskab ApS CVR: 42299529 Niels Jernes Vej 10, 9220 Aalborg Øst, Denmark Email: kontakt@mitberedskab.dk Website: https://mitberedskab.dk [Bekræftet 29. mar. 2026]


Changelog

VersionDateChangeResponsible
1.02026-02-11Document created and published on mitberedskab.dkTobias (CTO)
1.12026-03-04AI tools (AWS Bedrock) added as sub-processor in Section 5. Date updatedAnders (CEO)
1.22026-03-05Marketing cookies (Facebook, LinkedIn, Google Ads) added in Sections 4, 5, 6, 7 and 13. Cookie banner updated with category consentAnders (CEO)
1.32026-08-19Crisp (live chat) added as sub-processor in Section 5 and to the cookie table in 13.2. Footnote marker corrected for Meta/LinkedIn/Google Ads. Cookie table updated for GA4 (_ga_*) and extended with consent, Crisp and LinkedIn keys. Consent now expires after 12 months, and a “Cookieindstillinger” control was added to the footer so consent can be withdrawnAnders (CEO)
1.42026-08-21The tables in Section 5 and 13.2 are now machine-generated from an internal register and automatically checked on every release, so they cannot diverge from the website’s actual behaviour. New deletion guide in 13.4. The live chat (Crisp) now loads only when you click the chat button yourself, never automatically. Consent is stamped with a version so it can be tied to the banner version that collected it. “Afvis alle” now carries the same visual weight as “Accepter alle”Anders (CEO)

For any change to this document: (1) update the version number in the header, (2) set “Last updated” to the date of change, (3) add a new line to this changelog, and (4) record the change in the folder’s Changelog.md.


This policy is governed by Danish law. In the event of any discrepancy between this English version and the Danish version, the Danish version shall prevail.